mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Scope integration test doubles alongside script-local helpers
This commit is contained in:
1 parent
4c2193964e
commit
9bd56a0840
3 files changed
+23
-17
No files matched your search
@@ -1,5 +1,7 @@
|
||||
# Composed #362/#363/#365 behavior, using mock registry/CIM and temporary journals only.
|
||||
$ErrorActionPreference = 'Stop'
|
||||
# Keep mocks in the same script scope as dot-sourced helpers/imported commands;
|
||||
# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks.
|
||||
$repo = Split-Path $PSScriptRoot -Parent
|
||||
$script:ScriptRoot = $repo
|
||||
. (Join-Path $repo 'scripts/Configuration.ps1')
|
||||
@@ -29,30 +31,30 @@ function Reset-Mocks($Outgoing = 0, $Domain = 2, $ProductType = 2) {
|
||||
$script:writes = 0; $script:readFails = $false; $script:writeFails = ''
|
||||
$script:roleFails = $false
|
||||
}
|
||||
function global:Get-CimInstance {
|
||||
function Get-CimInstance {
|
||||
param($ClassName, $Property, $Namespace, $ErrorAction)
|
||||
if ($ClassName -eq 'Win32_OperatingSystem') {
|
||||
if ($script:roleFails) { throw 'Mock role query failure' }
|
||||
return [pscustomobject]@{ ProductType = $script:productType }
|
||||
}
|
||||
}
|
||||
function global:Test-Path {
|
||||
function Test-Path {
|
||||
param($LiteralPath, $Path, $ErrorAction)
|
||||
$target = if ($LiteralPath) { $LiteralPath } else { $Path }
|
||||
if ($target -like 'HKLM:*') { return $true }
|
||||
Microsoft.PowerShell.Management\Test-Path -LiteralPath $target
|
||||
}
|
||||
function global:Get-ItemProperty {
|
||||
function Get-ItemProperty {
|
||||
param($LiteralPath, $ErrorAction)
|
||||
if ($script:readFails) { throw 'Mock registry read failure' }
|
||||
return [pscustomobject]$script:registry
|
||||
}
|
||||
function global:Get-WelaRegistryState {
|
||||
function Get-WelaRegistryState {
|
||||
param($Path, $Name)
|
||||
if ($script:readFails) { throw 'Mock registry read failure' }
|
||||
[pscustomobject]@{ KeyExists = $true; ValueExists = ($null -ne $script:registry[$Name]); Value = $script:registry[$Name]; Type = 'DWord' }
|
||||
}
|
||||
function global:Set-ItemProperty {
|
||||
function Set-ItemProperty {
|
||||
param($LiteralPath, $Name, $Value, $Type, $ErrorAction)
|
||||
# Assert the actual mutation cannot run before its matching journal entry.
|
||||
$journal = Join-Path $script:currentContext.BackupPath 'before.jsonl'
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
# Profile command + verified configuration integration. No Windows policy is touched.
|
||||
$ErrorActionPreference = 'Stop'
|
||||
# Keep mocks in the same script scope as dot-sourced helpers/imported commands;
|
||||
# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks.
|
||||
$repo = Split-Path $PSScriptRoot -Parent
|
||||
$script:ScriptRoot = $repo
|
||||
Import-Module (Join-Path $repo 'modules/AuditProfiles.psm1') -Force
|
||||
@@ -44,16 +46,16 @@ function Reset-Run([string]$Profile = 'cis-win11-v4-l1', [switch]$DryRun) {
|
||||
$script:cleanup.Add($script:BackupPath)
|
||||
$script:cleanup.Add($script:ResultsPath)
|
||||
}
|
||||
function global:TestWindows { return $true }
|
||||
function global:TestAdministrator { return $true }
|
||||
function global:Get-WelaHostContext { [pscustomobject]@{ Role = 'Client'; Build = $script:hostBuild } }
|
||||
function global:Get-WelaEffectiveAuditPolicy { return $script:state.Clone() }
|
||||
function global:Get-WelaNativeAuditPolicy {
|
||||
function TestWindows { return $true }
|
||||
function TestAdministrator { return $true }
|
||||
function Get-WelaHostContext { [pscustomobject]@{ Role = 'Client'; Build = $script:hostBuild } }
|
||||
function Get-WelaEffectiveAuditPolicy { return $script:state.Clone() }
|
||||
function Get-WelaNativeAuditPolicy {
|
||||
param($Guid)
|
||||
if (-not $script:state.ContainsKey($Guid)) { throw "Mock missing policy: $Guid" }
|
||||
return $script:state[$Guid]
|
||||
}
|
||||
function global:Invoke-WelaNative {
|
||||
function Invoke-WelaNative {
|
||||
param($FilePath, $Arguments)
|
||||
if ($FilePath -ne 'auditpol.exe' -or $Arguments[0] -ne '/set') { throw 'Unexpected native mutation' }
|
||||
$guid = ($Arguments | Where-Object { $_ -like '/subcategory:*' }) -replace '^/subcategory:\{([^}]+)\}$', '$1'
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
# Safety regressions use extracted dispatcher statements with stub mutators and mocked registry APIs.
|
||||
# Never dot-source WELA or invoke configure-sacl/update-rules implementations from this test.
|
||||
$ErrorActionPreference = 'Stop'
|
||||
# Keep mocks in the same script scope as dot-sourced helpers/imported commands;
|
||||
# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks.
|
||||
$repo = Split-Path $PSScriptRoot -Parent
|
||||
$tokens = $null; $errors = $null
|
||||
$ast = [Management.Automation.Language.Parser]::ParseFile((Join-Path $repo 'WELA.ps1'), [ref]$tokens, [ref]$errors)
|
||||
@@ -54,26 +56,26 @@ function New-RaceContext([switch]$Prompt) {
|
||||
$script:cleanup.Add($path)
|
||||
New-WelaConfigurationContext -Auto:(-not $Prompt) -BackupPath $path
|
||||
}
|
||||
function global:Get-WelaOutgoingNtlmState {
|
||||
function Get-WelaOutgoingNtlmState {
|
||||
# The first display is deliberately stale; the shared runner must trust its own fresh read.
|
||||
[pscustomobject]@{ Readable = $true; Value = 0; Description = 'Allow all (initial read)'; PolicySource = 'mock' }
|
||||
}
|
||||
function global:Get-WelaRegistryState {
|
||||
function Get-WelaRegistryState {
|
||||
param($Path, $Name)
|
||||
if ($script:journalWritten -and $script:prewriteReadFails) { throw 'Mock prewrite read failure' }
|
||||
[pscustomobject]@{ KeyExists = $true; ValueExists = $true; Value = $script:value; Type = $script:type }
|
||||
}
|
||||
function global:New-WelaRegistryKey { param($Path) }
|
||||
function global:Set-ItemProperty {
|
||||
function New-WelaRegistryKey { param($Path) }
|
||||
function Set-ItemProperty {
|
||||
param($LiteralPath, $Name, $Value, $Type, $ErrorAction)
|
||||
$script:value = $Value; $script:type = $Type; $script:writes++
|
||||
}
|
||||
function global:Read-Host {
|
||||
function Read-Host {
|
||||
param($Prompt)
|
||||
if ($null -ne $script:changeOnPrompt) { $script:value = $script:changeOnPrompt }
|
||||
return 'Y'
|
||||
}
|
||||
function global:Add-Content {
|
||||
function Add-Content {
|
||||
param($LiteralPath, $Value, $Encoding, $ErrorAction)
|
||||
process {
|
||||
# Preserve real temporary recovery files; only the mocked policy state changes.
|
||||
|
||||
Reference in new issue
Block a user